# Data privacy & compliance

> Munsit is built to meet the requirements of regulated, production-grade voice AI systems, where data privacy, security, and control are non-negotiable. Compliance is enforced at the architecture level — not through policy documents.

## HIPAA compliance

Munsit supports **HIPAA-compliant deployments** through an explicit **HIPAA Mode**. When HIPAA Mode is enabled:

| Guarantee | Detail |
| --- | --- |
| **No stored recordings** | No call recordings are stored on Munsit servers. |
| **In-memory processing** | Audio streams are processed in-memory only. |
| **Zero persistence** | Zero persistent storage of voice data. |
| **Customer ownership** | All data ownership remains with the customer. |
| **No secondary usage** | No secondary usage of audio for training or analytics. |

> Available everywhere. HIPAA Mode is available across SaaS, Dedicated VPC, and On-Prem deployments — so voice AI companies and enterprises can confidently use Munsit for healthcare, financial services, government, and regulated enterprise workloads without compromising compliance.

## Data ownership & control

Munsit follows a **customer-first data model**:

| Principle | Detail |
| --- | --- |
| **Full ownership** | Customers retain full ownership of all audio, transcripts, and metadata. |
| **Opt-in retention** | No recordings are retained unless explicitly configured by the customer. |
| **Deployment-level controls** | Deployment-level controls determine retention, logging, and access policies. |
| **Sovereign-ready** | Suitable for air-gapped and sovereign environments. |

## Security & certifications

Munsit is designed with enterprise security standards from day one.

| Standard | Status |
| --- | --- |
| **HIPAA** | Certified |
| **SOC 2** | _In progress_ |
| **ISO 27001** | _In progress_ |

Security controls already implemented include:

| Control |
| --- |
| Strict access isolation per tenant |
| Encrypted data in transit |
| Environment-level security boundaries (SaaS, VPC, On-Prem) |
| Operational auditability for enterprise customers |

## Built for regulated voice AI

Munsit is trusted in environments where voice data is sensitive by default, retention must be explicitly disabled, infrastructure must support **on-prem or sovereign hosting**, and compliance is enforced at the architecture level. It enables teams to build real-time voice AI systems with confidence — without sacrificing privacy, performance, or control.

- [Self hosting](/deployment/self-hosting) — Run Munsit inside your own data centre or private environment. — `on-prem guide`

- [Support](/support) — Talk to the team about compliant deployment options. — `guide`

## Customer responsibility

Munsit provides the underlying speech and inference infrastructure but does not control, moderate, or assume responsibility for customer-generated content. Customers are **solely responsible** for:

| Responsibility |
| --- |
| The content generated by applications using Munsit |
| Ensuring generated outputs comply with applicable laws, regulations, and industry standards |
| Implementing appropriate human review, guardrails, and usage policies where required |
